High severity8.3NVD Advisory· Published Feb 22, 2024· Updated Jun 17, 2026
CVE-2024-0220
CVE-2024-0220
Description
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
Affected products
6cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:br-automation:automation_studio:*:*:*:*:*:*:*:*range: <4.6
- (no CPE)range: 4.0
cpe:2.3:a:br-automation:technology_guarding:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:br-automation:technology_guarding:*:*:*:*:*:*:*:*range: <1.4.0
- (no CPE)
- (no CPE)range: 1.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.